TRACK: THREATS AND DETECTION

What ITDR covers, and what it does not

SHORT ANSWER

ITDR watches identity systems for attacks and responds to them. It covers directory attacks well, sessions and tokens less evenly, and it does not replace good sign-in or good hygiene.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

2 min read

Identity threat detection and response grew out of a simple observation: attackers who get one account usually aim for the directory, because the directory hands out every other account. Tools in this category watch identity systems such as Active Directory and cloud identity providers for signs of that climb.

What it detects

The classic list is directory attacks: password spraying, Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync, all named on Silverfort's ITDR page. Microsoft Defender for Identity groups its detections by stage: reconnaissance, compromised credentials, lateral movement and domain dominance. Session attacks are covered by tools that watch the identity provider itself: Okta Identity Threat Protection names session hijacking and token theft.

How it responds

Responses range from an alert in a console to blocking the attempt before access is granted. Silverfort blocks, challenges with MFA or ends the session inline. Okta can end sessions across supported apps with Universal Logout. Semperis rolls back malicious changes to Active Directory and Entra ID.

What it does not do

ITDR does not make sign-in harder to phish, and it does not remove the stale accounts and long-lived secrets attackers use. Those belong to the identity provider and to hygiene work. It also cannot detect what it cannot see: a tool that monitors Active Directory will not see an attack on a SaaS app's own accounts.

When comparing ITDR tools, ask three questions: which systems it watches, which attacks it can stop rather than report, and what it does after a detection.

See ITDR solutions compared

Related pages

Sources

NEXT LESSON

Phishing-resistant sign-in: passkeys, FIDO2 and assurance levels

3 min read